|
279301
|
9.8 |
CRITICAL
Network
|
status2k
|
status2k
|
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
|
CWE-20
Improper Input Validation
|
CVE-2014-5091
|
2024-11-21 11:11 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279302
|
9.8 |
CRITICAL
Network
|
sphider sphider-plus sphiderpro
|
sphider sphider-plus sphider_pro
|
A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2014-5087
|
2024-11-21 11:11 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279303
|
8.8 |
HIGH
Network
|
kemptechnologies
|
load_master
|
A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
|
CWE-352
Origin Validation Error
|
CVE-2014-5288
|
2024-11-21 11:11 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279304
|
7.5 |
HIGH
Network
|
open-xchange
|
open-xchange_appsuite
|
Multiple absolute path traversal vulnerabilities in documentconverter in Open-Xchange (OX) AppSuite before 7.4.2-rev10 and 7.6.x before 7.6.0-rev10 allow remote attackers to read application files vi…
|
CWE-22
Path Traversal
|
CVE-2014-5236
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279305
|
9.6 |
CRITICAL
Network
|
eucalyptus
|
eucalyptus_management_console
|
Cross-site scripting (XSS) vulnerability in Eucalyptus Management Console (EMC) 4.0.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5039
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279306
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk2
|
Multiple integer overflows in the Pre-EFI Initialization (PEI) boot phase in the Capsule Update feature in the UEFI implementation in EDK2 allow physically proximate attackers to bypass intended acce…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4860
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279307
|
6.8 |
MEDIUM
Physics
|
tianocore
|
edk2
|
Integer overflow in the Drive Execution Environment (DXE) phase in the Capsule Update feature in the UEFI implementation in EDK2 allows physically proximate attackers to bypass intended access restri…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2014-4859
|
2024-11-21 11:11 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279308
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central manageengine_desktop_central_managed_service_providers
|
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90055 allows rem…
|
CWE-22
Path Traversal
|
CVE-2014-5007
|
2024-11-21 11:11 |
2020-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279309
|
7.8 |
HIGH
Local
|
open-xchange
|
open-xchange_appsuite
|
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read arbitrary files and possibly other unspecified imp…
|
CWE-611
XXE
|
CVE-2014-5238
|
2024-11-21 11:11 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279310
|
7.5 |
HIGH
Network
|
iii
|
sierra
|
Innovative Interfaces Sierra Library Services Platform 1.2_3 does not properly handle query strings with multiple instances of the same parameter, which allows remote attackers to bypass parameter va…
|
NVD-CWE-Other
|
CVE-2014-5138
|
2024-11-21 11:11 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|